ZyXEL Communications SSL 10 Release note

Type
Release note

This manual is also suitable for

www.zyxel.com
ZyXEL
Firmware Release Note
ZyWALL SSL10
Release 1.00(AQH.6)
Date: Aug, 12, 2008
Project Leader: Julian Wu
www.zyxel.com ZyWALL SSL 10
Release 1.00(AQH.6)
Release Note
Date: Aug, 12, 2008
Supported Platforms:
ZyXEL ZyWALL SSL 10
Versions:
ZLD Version: 1.00(AQH.6) | 2008-08-01 16:40:00
Bootbase: V1.0 | 2007-03-23 09:17:32
Notes:
1. The default device administration username is “admin”, password is “1234”.
2. The default LAN subnet is 192.168.1.0/24 with LAN IP as 192.168.1.1.
3. The default WAN interface is eth1, and it will automatically get IP address using
DHCP by default.
4. User can update this firmware by using GUI
www.zyxel.com
Known Issues:
System:
SSL VPN:
1. [SPR: 061018594]
[Symptom] “Add To Favorite” is not supported in Mozilla, Firefox and Netscape
browsers.
A pop-up message informs this when user uses any of the above browsers.
[Work around] Use IE browser to bookmark the page.
2. [SPR: 061024808]
[Symptom] Web application with WinMail 4.3 can login but can't compose and send
mail. This is not bug on SSL10 rather due to improper java scripting on the WinMail
server
[Work around] Change the PHP script to comply so that Send Mail through SSL10
can work. Otherwise use SSL-VPN SecuExtender to use Win Mail.
3. [SPR: 061103195]
[Symptom] After 14 hours of stress, download file failed in File Sharing throwing a
warning message “Connect to URL/share1 denied by ACL”.
4. [SPR: 070314942]
[Symptom] Full tunnel mode failed if a client is a Windows 2003 server.
5. [Symptom] Sometimes compose mail in OWA is not working through SSL10 when
trying from a Vista IE7 client.
[Work around] OWA should have Exchange 2003 SP2 to allow compose window
render work properly. If it is still not working after installing Exchange SP2, after
login to OWA through SSL10, click on link “Download” or “Re-Install” under
“Option Æ Email Security”.
Features:
Modifications in 1.00(AQH.6)b4
1. [BUG FIX]
Symptom:
Hardware test program failed during manufacturing process.
Condition:
1. Updated HTP application which fixes the issues.
Modifications in 1.00(AQH.6)b3
www.zyxel.com
1. [BUG FIX] 080528793
Symptom:
After a period, Device doesn't respond for SSL connection and sslvpn deamon is
dead.
Condition:
1. After a period, Device doesn't have any action but sslvpn deamon is dead.
2. HTTPS 443 port can not work.
2. [BUG FIX] 080529844
Symptom:
Sometime device boot on, users can not resolve google, but device can.
Condition:
1. Sometime device boot on, users can not resolve google in LAN side, but device
can.
2. User ping www.google.com.tw will fail, but device can.
3. [BUG FIX] 080603154
Symptom:
Some of the EPS parameter can not work.
Condition:
1. When looking for latest Fix Packs (for example KB923789) EPC is failing.
2. EPC Registry Name and Value are accepting only alpha numeric characters.
3. Advanced Settings\Process Name (Some execute file don't work in Process, for
example cmd.exe and csrss.exe)
4. Reverse proxy mode doesn't generate ssldll.log file in C disk.
4. [BUG FIX] 080604255
Symptom:
Device does send Log message to admin, the device is always check SMTP
authentication even if disable SMTP authentication.
Condition:
1. Maintenance\Log\Log Setting\System Log edit.
2. Check SMTP authentication option box is disable
3. Device always have send SMTP authentication to mail server
5. [BUG FIX] 080611669
Symptom:
Failed to create a new certificate with same Certificate Name even though
previous SCEP certificate is not displayed.
Condition:
1. Request a SCEP certificate, the certificate name is “test_scep” will succeed.
2. Request a SCEP certificate, the certificate name is “SCEP” will succeed. But
the SCEP certificate does not display in GUI of My certificate.
3. Crate a certificate by device self-sign, the certificate name is “SCEP” will
failed. Because message show “Private Key Identifier already exists”
www.zyxel.com
6. [BUG FIX]
Symptom:
Box is failing to send log email when using ArGoSoftMail SMTP Server.
Condition:
1. Setup ArGoSoft Mail Server in the network.
2. In Device Log Settings Configure SMTP server as ArGoSoft Mail Server.
3. Device cannot send log emails to this SMTP Server.
Modifications in 1.00(AQH.6)b2
1. [BUG FIX]
Symptom:
Failed to send an email with bigger mail text content of size around 15KBytes.
Condition:
1. Login to portal and access OWA link
2. Type a new email with the content around 15Kbytes.
3. After clicking on Send, a pop-up will be thrown saying “Unknown” and mail
will not be sent.
Modifications in 1.00(AQH.6)b1
1. [BUG FIX] 070801002
Symptom:
When using the SSL10 in the DMZ-zone of a ZyWALL and using port-translation
an user can log into the SSL10. However, none of the SSL10 are working (full
tunneling mode, port forwarding or reverse proxy) if the service port on the front
end device listen on non-443 port.
Condition:
1. The user only has one single public IP and TCP 443 already used from another
web application. For such application, the only solution is to let the front end
device listen on different port. However, the current design with SSL 10
cannot make this work.
2. [BUG FIX] 080402220
Symptom:
Improper error when user tries to download file for which EFS is turned on.
Condition:
1. Enable EFS on a File Share.
2. Once user login to portal try to download a file from the share which has EFS
enabled.
3. Portal displays “Connect to share <IP>/share denied by ACL”.
3. [BUG FIX]
Symptom:
Firewall is unable to filter the traffic to external machines though policy action is
configured as Deny.
www.zyxel.com
Condition:
1. Create a Full Tunnel user and configure Firewall policy as ALL to ALL with
action Deny.
2. Login to portal and try to ping a machine in the external network of SSL10.
3. Though ping to LAN network of SSL10 blocked, ping is allowed to external
network machines.
4. [BUG FIX]
Symptom:
Device is not responding until reboot after sending an email in OWA with
specific content.
Condition:
1. Login to portal and access OWA link.
2. Type a new email with the content (specific content provided by customer).
3. After clicking on Send, SSLVPN process dies and box will not respond further
until reboot.
5. [ENHANCEMENT]
Symptom:
Take out few commands which set fixed IP Address and MAC to Ethernet
interfaces during boot-up.
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6

ZyXEL Communications SSL 10 Release note

Type
Release note
This manual is also suitable for

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI